Vulnerability Assessment
Systematic identification and triage of vulnerabilities across your IT estate, ranked by exploitability in your environment rather than by raw CVSS.
What you receive
- Authenticated and unauthenticated scanning
- Exploitability triage against your actual exposure
- Prioritised remediation plan with effort estimates
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
You inherited an estate you did not build
After an acquisition or an outsourcing handover, nobody can say which hosts are patched, which are still supported and which are reachable from outside. An assessment gives you the inventory and the patch position in one pass, before you own the consequences.
Your scanner produces more work than capacity
Raw CVSS ranks a vulnerability by its worst possible context rather than by yours. Triage against actual exposure — is it reachable, is it authenticated, is there a working exploit — turns an unbounded backlog into a list bounded by what the team can actually finish.
You need recurring evidence, not a one-off
Several regimes ask for scanning at a fixed cadence and for evidence that findings were resolved and then rescanned. A standing assessment produces that record as a by-product, rather than as a reconstruction the week before the audit.
How it runs
Scoping call
Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.
Written proposal
Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.
Delivery
Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.
Readout and retest
A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
Assessment finds and ranks; it does not exploit. Proving a finding is reachable end to end through a chain of weaknesses is a penetration test.
Automated coverage does not reach business logic — broken authorisation between two valid users looks like ordinary traffic to a scanner.
It says nothing about detection or response. A scan nobody noticed returns exactly the same report as one that raised every alert you own.
- PCI DSS 4.0.1 Req. 11.3
- Internal scans at least every three months and after significant change; external scans quarterly by an Approved Scanning Vendor.
- ISO/IEC 27001:2022 Annex A 8.8
- Requires information on technical vulnerabilities to be obtained, exposure evaluated and appropriate measures taken.
- NIS2 Directive (EU) 2022/2555, Art. 21(2)(e)
- Names vulnerability handling and disclosure among the minimum measures essential and important entities must have in place.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Is this a scan you resell back to us?
The scan is the input, not the product. The work is credentialed coverage, clearing false positives, attaching each host to an owner who can act, and deciding which findings your environment actually makes exploitable.
Why do you want credentials for the scan?
Unauthenticated scanning reads banners and guesses at versions, so it both misses packages patched in place and invents findings that are not there. Credentialed scanning reads the installed inventory, which is why the two views rarely agree.
How often is often enough?
Frequency should follow your rate of change, not the calendar — an estate that deploys weekly is stale a week after the scan. Regulated cadences such as quarterly scanning are a floor set for audit, not an answer to that question.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.